216.73.217.22

CVE-2025-27918

· Published 06/11/2025 18:15 · Modified 08/12/2025 17:16

Labels: CVE-2025-27918 2025-11-06CVE-2025-27918CWE-190[email protected]

Essential information

Published
06/11/2025 18:15
Modified
08/12/2025 17:16
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.

NVD status

Status
Modified — CVE has been amended by a source (CVE Primary CNA or another CNA). Analysis data supplied by the NVD may be no longer be accurate due to these changes.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
anydesk / anydesk cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*

References